SQL injection is still possible with XPDO. I ran into a case awhile back where SELECT queries using IN() were vulnerable (or at least produced a SQL error. IN() was expecting numerical values from a snippet property, and the property got the values from a GET request variable with comma-separated list of IDs. Bad idea - the values were not escaped by XPDO, and they weren't sanitized in the snippet either.
Personally, I always sanitize my input variables in every script I write. Every $_* variable is automatically cleaned with HTMLPurifier or converted into HTML entities, trimmed for whitespace, "../", "`", "[[" and "]]" tags are encoded to prevent abuse in the web context. I manually convert numerics to integers and make sure they're within the expected range. If it's a string and I know the possible values, I compare it against an array of expected values, and set it to a default if it's invalid.
This is all before being used in a query, or being displayed to a user.
There's more, but I think you can get the gist of it. I'm paranoid when it comes to code, because I've found that if you're not, it'll find a way to bite you in the backside.